PkgRadar

PyPI · pypi.org

nhmpy

Py Name Typosquat: Name `nhmpy` is one edit away from popular package `numpy` — likely typosquat.

Why PkgRadar flagged 2.4.7

SeveritySignalEvidence
highPy Name TyposquatName `nhmpy` is one edit away from popular package `numpy` — likely typosquat.
mediumLarge Native Blob6622576 bytes · nhmpy/_core/_multiarray_umath.cpython-311-darwin.so
mediumLarge Native Blob25207040 bytes · nhmpy/.dylibs/libscipy_openblas64_.dylib
mediumLarge Native Blob6786304 bytes · nhmpy/.dylibs/libgfortran.5.dylib

Scanned versions

VersionVerdictScoreScanned (UTC)
2.4.7High risk702026-06-07
2.4.6High risk702026-06-07

Block this in CI

PkgRadar gates nhmpy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi nhmpy==2.4.7